Legal

Data Protection Policy

Internal policy governing how Settl handles personal data

Effective date: 22 July 2026Version 1.0Prepared under the Digital Personal Data Protection Act, 2023 (India)
Important — draft for legal and security review. This Data Protection Policy is a comprehensive internal draft prepared for Settl and reflects the obligations Settl has already made to Customers and Debtors in its Privacy Policy and Terms & Conditions. It is not legal advice and has not been reviewed by an advocate or security auditor. It must be checked against Settl's actual technical and organisational practices before adoption — a policy your team does not follow creates more risk than no policy at all. Complete every [● ...] placeholder and circulate to all staff on adoption.

1. Purpose & Scope

This Data Protection Policy (“Policy”) sets out how AIVONT AI LABS (“Settl”, “we”, “us”) organises itself internally to meet its obligations under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

This Policy is an internal governance document. It applies to every employee, contractor, intern and consultant of Settl, having its registered office at 559-569, Tower-B1, Gurgaon, Haryana 122018, India, and to all systems, tools and vendors that store or process personal data on Settl's behalf. It does not replace, and must remain consistent with, Settl's public-facing Privacy Policy and its Terms & Conditions, which describe our commitments to Customers, Users and Debtors. Where this Policy and either of those documents appear to conflict, the public commitment governs and this Policy must be corrected.

This Policy covers all personal data Settl touches in any capacity, whether Settl acts as Data Fiduciary or as Data Processor (see Section 3).

2. Definitions

  • Personal Data — any data about an individual who is identifiable by or in relation to such data.
  • Data Principal— the individual to whom personal data relates (in our context, a Customer's authorised User, or a Debtor).
  • Data Fiduciary — the party that determines the purpose and means of processing personal data.
  • Data Processor — the party that processes personal data on behalf of a Data Fiduciary and on its instructions.
  • Debtor Data — names, mobile numbers, invoice particulars and message history that a Customer uploads or syncs to Settl in order to send payment reminders.
  • Personal Data Breach — any unauthorised processing, disclosure, alteration, loss or destruction of personal data that compromises its confidentiality, integrity or availability.
  • Sub-processor — a third party engaged by Settl to process personal data in the course of providing the Services.

3. Roles & Responsibilities

3.1 Settl's dual role

Settl is a Data Processor in respect of Debtor Data, which it processes solely on the documented instructions of the Customer (the Data Fiduciary for that data). Settl is the Data Fiduciary in respect of Customer account data, billing data, and website/product usage data. Every employee must know which role applies before acting on a data request — see the table in Section 5 of the Privacy Policy for the authoritative mapping.

3.2 Accountable roles

RoleResponsibility
Grievance Officer / Data Protection ContactSingle point of accountability for DPDP Act compliance; receives and tracks Data Principal requests and breach reports; liaises with the Data Protection Board of India. Named contact: [● OFFICER NAME]
Engineering / Security leadOwns technical safeguards (Section 7), access provisioning, encryption, logging and incident response.
Founders / ManagementUltimate accountability for this Policy, budget for security controls, and sign-off on new features that process Debtor Data (e.g. AI-based intent detection).
All employees & contractorsMust complete the training in Section 15, follow least-privilege access practices, and report suspected incidents immediately to the Grievance Officer.

4. Data We Are Responsible For

The categories below mirror Section 3 of the Privacy Policy; this Policy adds internal handling notes for each.

CategoryInternal handling notes
Debtor DataNames, mobile numbers, invoice numbers, amounts, due dates, payment status, message content. Processed only per Customer instruction; never used for our own purposes, advertising, or to train general-purpose AI models.
Customer account & billing dataBusiness details, user names, emails, login credentials (hashed), GSTIN, subscription and invoice records. Settl is Data Fiduciary; ordinary internal-access rules apply.
Website & product usage dataDevice, log and analytics data collected from visitors and Users. Used only in aggregated or de-identified form for product improvement unless otherwise stated.

We do not knowingly collect sensitive personal data (biometric, health, caste/religious identifiers, financial account credentials) and do not knowingly collect data relating to children. Any engineering proposal that would introduce collection of such data must be escalated to the Grievance Officer before build begins.

5. Data Protection Principles

Every system design decision, feature build and vendor selection at Settl must be checked against these principles, which reflect Section 8 of the DPDP Act:

  • Lawfulness & purpose limitation — process personal data only for the purpose it was collected or instructed for.
  • Data minimisation— collect and retain only what a feature genuinely needs; do not add fields “just in case”.
  • Accuracy — provide Customers and Users a straightforward way to correct inaccurate data; do not silently infer or overwrite user-supplied data.
  • Storage limitation — apply the retention and deletion schedule in Section 10; do not keep data past its scheduled disposal date without a documented legal reason.
  • Integrity & confidentiality — apply the technical and organisational measures in Section 7 to every system that touches personal data, not only production databases.
  • Accountability — be able to show, on request, what data a system holds, why, and who can access it.

6. Processing Debtor Data as a Processor

Because Settl acts as a Data Processor for Debtor Data, engineering and support teams must observe the following at all times:

  • Process Debtor Data only to provide the Services (sending reminders, tracking replies, detecting payment intent) — never for Settl's own analytics, marketing, benchmarking or model training outside the provision of the Services to that Customer.
  • Do not act on a request from a Debtor to access, correct or delete their data directly — redirect them to the Customer (the Data Fiduciary) per Section 10 of the Privacy Policy, unless the request is an opt-out (Section 9 below), which we action immediately ourselves.
  • Provide reasonable technical assistance to a Customer who needs to respond to their own Data Principal requests or notify the Data Protection Board of a breach.
  • Flow down equivalent confidentiality and security obligations to every sub-processor that touches Debtor Data (Section 11).

7. Technical & Organisational Security Measures

These measures apply across all environments (production, staging, analytics, backups) that hold personal data:

  • Encryption of data in transit using TLS, and encryption of sensitive fields at rest.
  • Role-based access control, with staff access limited to what their function requires.
  • Audit logging of administrative actions on Customer and Debtor Data.
  • Hashed credential storage and support for multi-factor authentication on all Settl accounts, internal and Customer-facing.
  • Regular backups, security patching and vulnerability management on a documented cadence.
  • Contractual security obligations imposed on all sub-processors, verified before onboarding (Section 11).
  • Device and workstation controls for staff (screen locks, disk encryption, no storage of production exports on personal devices).

No system is perfectly secure. These measures reduce risk; they do not eliminate it. Every employee must report suspected unauthorised access immediately rather than waiting to confirm impact.

8. Access Control & Least Privilege

  • Production access to Debtor Data and Customer account data is granted only where an employee's role requires it, and is reviewed at least every six (6) months.
  • New joiners are provisioned the minimum access needed for their role; elevated access requires sign-off from the Engineering/Security lead.
  • Access is revoked on the employee's last working day as part of the offboarding checklist, including personal devices, shared credentials and third-party tool seats.
  • Shared or generic logins are not permitted for any system that holds personal data.

9. Handling Opt-Outs and Suppression

A Debtor who replies STOP on a WhatsApp thread must have their opt-out actioned within 60 seconds and recorded on the permanent suppression list, so that they are never contacted again through Settl regardless of any later re-upload of their number by a Customer. This is the one Debtor-facing request Settl actions directly rather than redirecting to the Customer.

10. Retention & Secure Disposal

Retention periods must match the Privacy Policy and Terms & Conditions exactly. Any change to a system's retention behaviour requires the schedule below to be updated first.

DataRetention period
Debtor Data & message historyLife of the account; deleted or irreversibly anonymised within 90 days of account termination (30 days for export, then deletion).
Opt-out / suppression recordsRetained indefinitely, in minimal form.
Billing and tax recordsAs required under the Income-tax Act, 1961, GST law and the Companies Act, 2013 — ordinarily 8 years.
Security and access logsUp to 12 months, or longer for an ongoing investigation.
Support communicationsUp to 24 months.
Marketing contact dataUntil consent is withdrawn.

Disposal must be irreversible — secure deletion or anonymisation such that the individual can no longer be identified — not merely hidden from the application layer.

11. Sub-processor & Vendor Management

  • Maintain a current internal list of all sub-processors (cloud hosting, WhatsApp Business Platform / Business Solution Providers, email delivery, error monitoring, product analytics, subscription payment processing) and keep it available to Customers on request.
  • Before onboarding a new sub-processor that will touch personal data, confirm it is bound by written confidentiality and data-protection obligations at least as strong as this Policy.
  • Settl remains responsible for a sub-processor's compliance; a vendor's failure does not shift responsibility away from Settl.
  • Review the sub-processor list at least annually and whenever a new category of data is introduced.

12. Data Principal Requests

Requests concerning Customer account data, or requests Settl is itself the Fiduciary for, must be logged, acknowledged within 48 hours, and resolved ordinarily within 15 days, within the statutory timelines under the DPDP Act. This includes:

  • Right to access — a summary of personal data held and processing activities undertaken.
  • Right to correction and erasure — correcting inaccurate/incomplete data, or erasing data no longer needed for its original purpose.
  • Right to nominate— recording a nominee to exercise rights on the Data Principal's behalf in the event of death or incapacity.
  • Right to withdraw consent — actioned immediately for any consent-based processing, such as marketing communications.

Requests concerning Debtor Data must be redirected to the relevant Customer, with reasonable technical assistance offered to that Customer so they can respond within statutory timelines (see Section 6).

13. Personal Data Breach Response

On suspicion or confirmation of a personal data breach, the following sequence applies:

  • Contain — the employee who discovers the issue notifies the Grievance Officer and Engineering/Security lead immediately, and takes reasonable steps to stop ongoing exposure (e.g. revoking a leaked credential).
  • Assess— Engineering/Security lead determines scope: which data, how many individuals, whether Debtor Data (Customer-affecting) or Settl's own Fiduciary data.
  • Notify— for Debtor Data, notify the affected Customer without undue delay and assist them in notifying the Data Protection Board of India and affected Data Principals. For Settl's own Fiduciary data, notify the Data Protection Board and affected persons directly, as required under the DPDP Act.
  • Record — log the incident, root cause, and remediation in an internal register, retained per Section 10.
  • Review — conduct a post-incident review and update this Policy or underlying controls where the review identifies a gap.

14. Data Protection Impact Assessment for New Features

Any new feature that introduces a new category of personal data collection, a new sub-processor, cross-border transfer, or a new automated/AI use of message content (such as payment-intent detection) must have a short written risk assessment reviewed by the Grievance Officer and Engineering/Security lead before launch. AI features may process message content solely to serve the originating Customer's own reminder workflow, and must not be used to train generally-available models.

15. Cross-Border Data Transfers

Personal data is primarily stored on servers located in India. Any transfer of personal data outside India must be limited to jurisdictions permitted under the DPDP Act, and must be subject to a written contractual safeguard with the receiving party before the transfer takes place.

16. Training & Awareness

  • All new employees and contractors complete a data protection induction covering this Policy before receiving access to any system holding personal data.
  • Refresher training is delivered at least annually, and immediately after any material change to this Policy or a significant incident.
  • Engineering staff receive additional training on secure coding, access control and the specific obligations of acting as a Data Processor.

17. Monitoring, Audit & Review

  • Access logs and the sub-processor list are reviewed on the cadence set out in Sections 8 and 11.
  • This Policy is reviewed at least annually, and whenever the DPDP Act, related rules, or Settl's Privacy Policy or Terms & Conditions change.
  • Material changes to this Policy must be reflected in the Privacy Policy and Terms & Conditions where they affect external commitments, and communicated to staff before taking effect.

18. Consequences of Non-Compliance

Failure to follow this Policy is treated as a disciplinary matter and may result in restricted access, disciplinary action up to and including termination, and — where a vendor or contractor is responsible — termination of the relevant contract. Nothing in this Policy limits Settl's rights or obligations under applicable law.

19. Policy Governance

Policy owner[● OFFICER NAME / GRIEVANCE OFFICER]
EntityAIVONT AI LABS
Review cycleAnnually, or on material regulatory or product change
Related documentsPrivacy Policy, Terms & Conditions, Incident Response runbook, Sub-processor list